Fun

Alex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiK

News Feed - 2024-05-15 05:05:19

Christopher Roark3 hours agoAlex bridge on BNB Smart Chain drained of $4.3M after suspicious upgrade — CertiKThe deployer account changed an Alex contract’s implementation address, and multiple tokens were subsequently drained from its bridge.887 Total views9 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksAccording to a May 14 report from blockchain security platform CertiK, the Alex protocol bridge on the BNB Smart Chain network suffered $4.3 million in suspicious withdrawals just after its contract was suddenly upgraded.


Alex is a Bitcoin layer-2 protocol. According to its official website, it provides decentralized finance applications on Bitcoin. Its bridges are used to transfer assets from other networks, such as BNB Smart Chain and Ethereum, to its own network.


Blockchain data confirms that the Alex deployer account performed five identical upgrades to the “Bridge Endpoint” contract on BNB Smart Chain beginning at 3:56 pm UTC. Approximately $4.3 million worth of Binance-Pegged Bitcoin (BTC), USD Coin (USDC), and Sugar Kingdom Odyssey (SKO) were subsequently removed from the BNB Smart Chain side of the bridge.


Because the upgrade was performed by the protocol’s deployer account, CertiK labeled the event “a possible private key compromise.” Source: CertiK


The upgrade transaction changed the implementation address to one ending in 7058. The new implementation is unverified bytecode, making it unreadable to human beings.


About 48 minutes after these upgrades began, the proxy address for the bridge contract called an unverified function on an address ending in 4848E. This resulted in 16 BTC ($983,000 at current prices), 2.7 million SKO ($75,000) and $3.3 million worth of USDC at 4:44 pm, being moved into the address at 484E.


The attacker may also be attempting to drain funds on other networks. At 5:41 pm, just minutes after the suspicious upgrade on BNB Smart Chain, a similar series of Alex upgrades occurred on Ethereum. In this case, the deployer upgraded the “artist address” to an unverified contract. Immediately afterward, an account ending in 05ed attempted to make two withdrawals from the “team address.” These withdrawals failed, producing a “not owner” error.


The 05ed account had no history before May 10. It created one unverified contract on May 10 and two more on May 14, indicating that it may be under the control of a malicious user.


At the time of publication, the Alex team has not confirmed the exploit or commented on the incident.


The Alex bridge wasn’t the only protocol to face a potential exploit in May. On May 13, decentralized exchange Equalizer announced that it had lost more than 2,000 of its own tokens from an attacker who siphoned them away in small increments over several days. The Gnus.ai hack on May 6 also resulted in $1.27 million worth of losses.


Related:CertiK discovered $5M security flaw in Wormhole bridge on Aptos# Bitcoin# Blockchain# Ethereum# Hackers# Private Keys# Cybersecurity# Hacks# DeFi# Layer2Add reaction

News Feed

Quidax Becomes the First African Crypto Exchange to be Listed on CoinMarketCap
Quidax Becomes the First African Crypto Exchange to be Listed on CoinMarketCap press release PRESS RELEASE. Last week Africa founded cryptocurrency exchange, Quidax, announced that
Former Heavyweight Boxing Champion Mike Tyson Asks Fans if They Prefer Bitcoin or Ethereum
Former Heavyweight Boxing Champion Mike Tyson Asks Fans if They Prefer Bitcoin or Ethereum On Saturday, former heavyweight boxing champion, Mike Tyson, asked his
Prashant Jha3 hours agoCoinbase Q2 earnings beat estimates amid Blackrock custody deal, institutional focusThe company beat estimates while non-trading revenue beat trading revenue.1560 Total views5 Total sharesListen to
Turner Wright5 hours agoUS lawmaker calls on SEC chair to reassess stance on crypto following Ripple rulingRep. Ritchie Torres shares a surname with Judge Analisa Torres in the SEC v. Ripple case and referred to the XRP
Stephen Katte21 hours agoHow security, education and regulation can mitigate rising crypto scamsCybersecurity experts say the crypto industry is a target for bad actors because it is a new technology that is rapidly evol
Rebranded Localcryptos Lets You Cash Out BTC Peer to Peer – Minus the Hassle of KYC 
Rebranded Localcryptos Lets You Cash Out BTC Peer to Peer – Minus the Hassle of KYC  If you’ve ever had a sudden need for fiat while all in crypto, you’ll understa
Bitcoin Stock To Flow Model Reveals $500,000 Price Target
Este artículo también está disponible en español. According to data from CoinMarketCap, Bitcoin (BTC) has gained by 0.66% in the past 24 hours with its market price now h
Asset Manager Stone Ridge’s NYDIG Sees Wall of Money Coming Into Bitcoin — Institutions Grow Beyond Owning BTC
Asset Manager Stone Ridge"s NYDIG Sees Wall of Money Coming Into Bitcoin — Institutions Grow Beyond Owning BTC The founder of Stone Ridge Asset Management and
Amaka Nwaokocha1 hour agoRipple exec and XRP community back SEC commissioner’s LBRY lawsuit dissentStuart Alderoty thanked Hester Peirce and suggested it might be time to submit an amicus brief.726 Total views6 Total s
New Push for Second Stimulus Checks: Analysts Predict When Another Relief Package Will Pass
New Push for Second Stimulus Checks: Analysts Predict When Another Relief Package Will Pass Many Americans are in need of second stimulus checks and a new corona
Bitcoin’s Difficulty Slides 7.32%, Reduction Marks the Largest Drop in 2022
Bitcoin"s Difficulty Slides 7.32%, Reduction Marks the Largest Drop in 2022 On Dec. 5, 2022, at block height 766,080, Bitcoin’s mining difficulty adjustment dropped 7.32% lower,
Amaka Nwaokocha1 hour agoGoogle to protect users in AI copyright accusationsGoogle explicitly stated that only seven products fall under this legal protection, excluding Google’s Bard search tool.484 Total views3 Total